Security Scan Report: forms.gle

Redirected to: https://docs.google.com/forms/d/e/1FAIpQLSf8E6N0MxhM1VZPwLMVdNRDr1vVFneXqq_AaCoX6s707CzUrQ/viewform?usp=send_form

Site favicon
Submitted: Nov 22, 2025, 1:24:20 PMCompleted: Nov 22, 2025, 1:25:33 PMpubliccompleted
Loading additional data...

Summary

This website contacted 16 IPs in 2 countries across 8 domains to perform 28 HTTP transactions. The main domain is docs.google.com.

Submitted URL: https://forms.gle/kkFWERydLssHsy4H7

Effective URL: https://docs.google.com/forms/d/e/1FAIpQLSf8E6N0MxhM1VZPwLMVdNRDr1vVFneXqq_AaCoX6s707CzUrQ/viewform?usp=send_formRedirected

The Cisco Umbrella rank of the primary domain is #9,953 of the top 1 million websitesTop 10K Site

AI Security Verdict

High Risk

Confidence: 85%

8
Risk Score

Phishing page impersonating Canada Post using a Google Form to collect data.

Risk Factors
Brand impersonation of Canada Post on a non‑official domain
Social‑engineering lure (fake delivery failure) prompting data submission
Use of a third‑party form service to harvest personal information
Domain age information unavailable

Details

Page Title

Delivery Failed

Scan Type

public

Language

🇩🇪

German

(80% confidence)

Category

unknown

(0%)

Domain Information

You're looking at domain 'forms.gle' on the .gle top-level domain. The core label 'forms' covers 5 characters containing 1 vowel alongside 4 consonants. Splitting it apart reveals one word: forms. Expect five characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://forms.gle/kkFWERydLssHsy4H7

Page Load Overview

0.73s
Total Load Time
28
HTTP Requests
8
Domains
1.1 MB
Total Size

Language Analysis

Primary Language

🇩🇪German
Code: de
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:de
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:de
Text Length:773 chars
Detector Agreement:100%

Website Classification

Primary Category

unknown0% confidence
Type: dynamic
Method: structural

All Detected Categories

No categories detected

Detected Features

OG: article

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
9142.250.184.195United States
AS15169GOOGLE
7142.250.186.131United States
AS15169GOOGLE
4216.58.206.78United States
AS15169GOOGLE
3142.250.185.202United States
AS15169GOOGLE
2142.250.186.35United States
AS15169GOOGLE
1142.250.181.225United States
AS15169GOOGLE
1142.251.140.174United States
AS15169GOOGLE
1199.36.158.100United States
AS54113FASTLY
12a00:1450:4001:81c::200eFrankfurt am Main, Hesse, Germany
AS15169GOOGLE
12a00:1450:4001:81d::2003Frankfurt am Main, Hesse, Germany
AS15169GOOGLE
2816--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1D673C80702116CBAEE6700E2D2555D0A7F9D133BB44761BAE2FC1FA33BDA8D91116367

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:G6CaUjSTGt0p4nCk0xzRZEW37bSHkoRijJfejuiYsGS+Wzf:EqFAue

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:73722:EK4sKAyMEAkBQLYARCqIgJAhSQFqAwAALmISYsmBCATkppOqhEIaESUK+YEwhgjZY4oAMwDNDCFkQQQaGCViAoFsBZhEEQEg

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:c3c3ffffefffffff
Perceptual Hash:b131676630ccce9e
Difference Hash:8e9e60949c681000
Wavelet Hash:c3c3cfdfc0c0f070
Color Hash:#78753a

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data